cbcvebase.

Kiteworks Core vulnerabilities

36 known vulnerabilities affecting kiteworks/core.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH19MEDIUM14LOW1

Vulnerabilities

Page 2 of 2
CVE-2026-23514P3MEDIUMCVSS 6.5v>= 9.2.0, < 9.2.22026-03-25
CVE-2026-23514 [MEDIUM] CWE-282 CVE-2026-23514: Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated users to access unauthorized content. Upgrade Kiteworks Core to version 9.2.2 or later to receive a patch.
nvd
CVE-2026-102124P3MEDIUMCVSS 6.5fixed in 9.5.02026-09-30
CVE-2026-102124 [MEDIUM] CWE-306 CVE-2026-102124: A Kiteworks appliance setup interface did not enforce authentication once the appliance had complete A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
nvd
CVE-2026-102092P3HIGHCVSS 8.7fixed in 9.5.02026-09-30
CVE-2026-102092 [HIGH] CWE-79 CVE-2026-102092: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could al Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.
nvd
CVE-2026-102145P3MEDIUMCVSS 6.6fixed in 9.5.12026-09-30
CVE-2026-102145 [MEDIUM] CWE-93 CVE-2026-102145: An authenticated administrator could cause the server to issue requests to, and interact with, inter An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through this interface. On its own this did not result in code execution.
nvd
CVE-2026-102126P3HIGHCVSS 8.1fixed in 9.5.12026-09-30
CVE-2026-102126 [HIGH] CWE-79 CVE-2026-102126: A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged admi
nvd
CVE-2026-102110P3MEDIUMCVSS 5.9fixed in 9.5.12026-09-30
CVE-2026-102110 [MEDIUM] CWE-306 CVE-2026-102110: An endpoint used during initial appliance setup did not require authentication and did not correctly An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely
nvd
CVE-2026-102134P3MEDIUMCVSS 5.4fixed in 9.5.12026-09-30
CVE-2026-102134 [MEDIUM] CWE-420 CVE-2026-102134: Kiteworks Core did not apply its gateway-level API security controls to every request authenticated Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.
nvd
CVE-2026-102136P4MEDIUMCVSS 6.3fixed in 9.5.12026-09-30
CVE-2026-102136 [MEDIUM] CWE-93 CVE-2026-102136: In multi-node deployments, an attacker who had already obtained code execution on one appliance node In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged
nvd
CVE-2026-102141P4MEDIUMCVSS 6.7fixed in 9.5.12026-09-30
CVE-2026-102141 [MEDIUM] CWE-73 CVE-2026-102141: Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch present on the target node.
nvd
CVE-2026-102111P4MEDIUMCVSS 4.9fixed in 9.5.02026-09-30
CVE-2026-102111 [MEDIUM] CWE-1284 CVE-2026-102111: Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently ren
nvd
CVE-2026-102140P4MEDIUMCVSS 4.9fixed in 9.5.12026-09-30
CVE-2026-102140 [MEDIUM] CWE-345 CVE-2026-102140: An authenticated administrator could initiate an administrative import using a file whose contents w An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.
nvd
CVE-2026-102107P4MEDIUMCVSS 4.6fixed in 9.5.12026-09-30
CVE-2026-102107 [MEDIUM] CWE-639 CVE-2026-102107: Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authent Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient unde
nvd
CVE-2026-102137P4MEDIUMCVSS 4.1fixed in 9.5.12026-09-30
CVE-2026-102137 [MEDIUM] CWE-434 CVE-2026-102137: An authenticated administrator could bypass the content validation applied to an administrative file An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This did not by itself result in code execution, which would require a separate vulnerability to run the stored file.
nvd
CVE-2026-102122P4MEDIUMCVSS 4.3fixed in 9.5.12026-09-30
CVE-2026-102122 [MEDIUM] CWE-863 CVE-2026-102122: Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. I Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
nvd
CVE-2026-102090P4MEDIUMCVSS 4.3fixed in 9.5.12026-09-30
CVE-2026-102090 [MEDIUM] CWE-601 CVE-2026-102090: Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF v Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedde
nvd
CVE-2026-102138P4LOWCVSS 3.3fixed in 9.5.12026-09-30
CVE-2026-102138 [LOW] CWE-918 CVE-2026-102138: An authenticated administrator on a node with an optional, separately licensed gateway role enabled An authenticated administrator on a node with an optional, separately licensed gateway role enabled could supply a connector URL that the server retrieved without sufficient validation of its scheme or destination, causing the server to issue requests to internal network services. Exploitation requires the licensed gateway role to be active.
nvd
Kiteworks Core vulnerabilities | cvebase